PyPI: aiohttp

CVE-2026-22815

Safety vulnerability ID: SFTY-20260401-83301

### Summary Insufficient restrictions in header/trailer handling could cause uncapped memory usage. ### Impact An application could cause memory exhaustion when receiving an attacker controlled request or response. A vulnerable web application could mitigate these risks with a typical reverse proxy configuration. ----- Patch: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36

Created at: Apr 1, 2026Updated at: Apr 1, 2026

Overview

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

Advisory

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

Affected Package

Affecting aiohttp package, versions
<= 3.13.3

Also affects

---

How to Fix

Upgrade
aiohttp
to
3.13.4
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more